Security Engineer

Tcs London Office
Charing Cross, United Kingdom
13 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
£ 40K

Job location

Remote
Charing Cross, United Kingdom

Tech stack

Microsoft Active Directory
Artificial Intelligence
Authentication Protocols
Cloud Computing
Computer Security
Information Leak Prevention
Data Security
Data Sharing
Digital Assets
Multi-Factor Authentication
Identity and Access Management
Microsoft Security Essentials
OAuth
OpenID
Powershell
Azure
Phishing
Security Assertion Markup Language (SAML)
Scripting (Bash/Python/Go/Ruby)
Mitre Att&ck

Job description

TCS is a purpose-led transformation company, built on belief. We do not just help businesses to transform through technology. We support them in making a meaningful difference to the people and communities they serve - our clients include some of the biggest brands in the UK and worldwide. For you, it means more to make an impact that matters, through challenging projects which demand ambitious innovation and thought leadership.

  • Gain exposure to innovative technology.
  • Work with customers and identify opportunities to support their strategy and improve various processes across functions.
  • Gain access to endless learning opportunities., As an MS Purview and M365 Defender XDR SME , you will be a proactive and skilled Microsoft Security Engineer or Analyst tasked with safeguarding digital assets by leveraging a comprehensive suite of Microsoft security technologies. The ideal candidate will have experience using Microsoft Defender XDR for managing and responding to threats, implement Microsoft Purview to ensure data compliance, and secure identities and access through Microsoft Entra ID. Core responsibilities will include threat management, proactive hunting for vulnerabilities, data protection, security posture management, and incident response. All of these will be based on collaborating with other teams to maintain and improve the organization's overall security posture., * Design, implement, and manage Data Loss Prevention (DLP) policies to prevent unauthorized data sharing including deploying and maintaining Information Protection policies (AIP/MPIP), such as sensitivity labels.
  • Configure and monitor policies to detect, investigate, and act on malicious or unintentional activities that could lead to data leakage or security incidents.
  • Monitor and investigate communications within the organization to detect and address potential violations of corporate policy or regulatory standards.
  • Manage and secure user, group, and workload identities including administering App & Enterprise App registrations and managing guest access for B2B (business-to-business) and B2C (business-to-consumer) scenarios.
  • Develop and manage Conditional Access (CA) policies to enforce granular access controls, including Multi-Factor Authentication (MFA), based on user, device, and location.
  • Implement and manage Self-Service Password Reset (SSPR) and Password Writeback to ensure seamless and secure user experience.
  • Act as a subject matter expert for the core components of the Defender XDR suite.
  • Manage endpoint protection, detection, and response across our device fleet.
  • Protect against email-based threats, including phishing, malicious attachments, and compromised links.
  • Monitor on-premises Active Directory signals to identify and investigate threats related to compromised identities.
  • Enforce security policies and provide threat protection across our cloud applications.
  • Prioritize and address critical vulnerabilities and misconfigurations based on a risk-based assessment.
  • Work with internal IT and other security teams to ensure the effectiveness of the platform.
  • Serve as a point of contact for external services like Microsoft Defender Experts for proactive hunting and expert guidance.
  • Document incident response procedures, create reports on security posture, and provide regular briefings to leadership.
  • Implement policies for records management and retention to ensure that data is retained according to legal and business requirements and securely disposed of when no longer needed.
  • Utilize DSPM capabilities to understand data risk, identify sensitive data across the environment, and implement controls to mitigate including managing data security posture related to AI applications and models .
  • Support legal and compliance teams by utilizing Purview's eDiscovery and audit capabilities for investigations.
  • Utilize Microsoft Entra ID Protection to identify and respond to compromised credentials and other identity-based risks.
  • Work closely with the Defender for Identity team to monitor on-premises Active Directory signals for threats.
  • Implement and maintain Privileged Identity Management (PIM) and Privileged Access Management (PAM) to provide just-in-time (JIT) access and enforce the principle of least privilege.
  • Ensure the proper configuration and integration of various authentication protocols, including SAML, OAuth, OIDC, and SCIM for application and service provisioning.
  • Secure Bring Your Own Device (BYOD) and other device access by implementing device-based access policies and configurations., Job Description We're looking for a Senior Security Engineer for our client in the data sector, based in London, on an initial 3 to 6 month contract paying up to £500 per day Outside IR35. This role offers hybrid working with an expectation to attend the office 3 days per..., Job Title: Information Security - (Data & AI team) Duration: Duration 4 months Contract Location: Hybrid - With infrequent site visit Daily Rate: Inside IR35 Hit Apply below to send your application for consideration Ensure that your CV is up to date, and that you have...

Requirements

Are you looking to utilize your skills in Microsoft?

Make a meaningful impact as a MS Purview and M365 Defender XDR SME!, * Previous experience in a cybersecurity role, with a strong focus on Microsoft security solutions.

  • In-depth practical knowledge of the Microsoft security stack, including Defender XDR, Purview, and Entra ID.
  • Experience with scripting languages, particularly PowerShell, for automation and management.
  • Familiarity with common cybersecurity frameworks and attack methodologies, such as the MITRE ATT&CK framework.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200; SC-300; SC-400).
  • Certified Information Systems Security Professional (CISSP).

Desirable skills/knowledge/experience:

  • Excellent analytical and problem-solving abilities.
  • Strong communication and collaboration skills to work effectively with technical and non-technical teams.
  • A proactive mindset and the ability to adapt to a fast-paced, evolving threat landscape.

Benefits & conditions

TCS is consistently voted as a Top Employer in the UK and globally. Our competitive salary packages feature pension, health care, life assurance, laptop, phone, access to extensive training resources and discounts within the larger Tata network.

We offer health & wellness initiatives and sports events; we are the proud sponsors of the London Marathon.

Diversity, Inclusion and Wellbeing

Tata Consultancy Services UK&I is committed to meeting the accessibility needs of all individuals in accordance with the UK Equality Act 2010 and the UK Human Rights Act 1998., Job Description Azure Access SME (SC Cleared) £600 per day inside IR35 Hybrid Working (must be UK based) We're looking for a hands-on Azure Access SME to take an established design and drive it through testing, change control, and full production implementation. This is...

About the company

A leading Tier One consultancy is seeking an experienced Microsoft Purview DLP Specialist to support a major security and compliance programme within a global banking client. Scroll down to find the complete details of the job offer, including experience required and..., A leading Tier One consultancy is seeking an experienced Microsoft Purview DLP Specialist to support a major security and compliance programme within a global banking client. This role will play a critical part in strengthening data protection controls and enhancing the...

Apply for this position